# Logstash grokparsefailure

**URL:** <https://discuss.elastic.co/t/logstash-grokparsefailure/250598>\
**Category:** Logstash\
**Created:** [October 1, 2020, 6:02am UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598 "2020-10-01T06:02:57Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 1, 2020, 2:43pm UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598/3 "2020-10-01T14:43:30Z")

</div>

> [@sandikata](#):
>
> Is it there any way (human readable) to debug what is causing grokparsefailure?

My suggestion for building complex grok patterns is [here](https://discuss.elastic.co/t/help-needed-in-grok/213827/2).

Note that grok debuggers (including kibana) and grok itself [sometimes](https://discuss.elastic.co/t/logstash-grok-not-parsing-multiline-pattern-properly/235033/4) interpret ambiguous patterns differently (and almost every pattern that uses DATA, or especially GREEDYDATA, is ambiguous).

---

_[View the full topic](https://discuss.elastic.co/t/logstash-grokparsefailure/250598)._
